Live data from Hacker News

Zoom to bring end-to-end encryption to all users, including non-paying

blog.zoom.us

111–120 of 557 posts

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#112

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

It wouldn't surprise me as recently the app tried to get me to trust an untrusted cert.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#113

Earlier quoted context omitted.

Agreed. I am always confused about the smackdown following a reversal from an arguably bad decision. We should be welcoming in hopes other companies note that being responsive is a good thing. Otherwise, it is just being stuck between rock and a hard place with no place to move.

What good are the apologies when they keep making new "mistakes"?

Exactly. And it's not like which video calling service one uses is a hill to die on. There are plenty of alternatives that aren't routinely bending the knee to authoritarian governments.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#115
post #103
post #6

"To make this possible, Free/Basic users seeking access to E2EE will participate in a one-time process that will prompt the user for additional pieces of information, such as verifying a phone number via a text message. Many leading companies perform similar steps on account creation to reduce the mass creation of abusive accounts." Perfect instrument to collect more personal data.

Is there any E2EE app that doesn't require verification? Whatsapp does. Even Signal requires a phone number.

https://riot.im/ lets you sign up without even an email

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#116
post #67

Earlier quoted context omitted.

There was a time when outside traffic routed through china. I believe zoom said it was a mistake. I'm not convinced that a setting alone should provide much confidence in terms of traffic routing considering that it can always be changed independent of what setting in the application you make.

> I believe zoom said it was a mistake. Yes, zoom said it was unintentional. For me, that's hard to believe. They weren't routing the call itself through China, they were just sending the encryption keys to a server in china. That seems pretty intentional. Even if they weren't routing the call through China from a user's perspective, their US server could still be sending the call data to China or recording the call…

I'm skeptical too.

Unfortunately for folks who are good actors in other non free countries countries... I find any sort of development or real world controls that are in a seriously non free country... automatically suspicious.

Even good individual developers who have the best of intentions in those places could be subject to pressure and the likelihood we'd ever hear about it is near zero in many of those places.

Granted that 'could' happen in more free countries, but I'll hedge my bets there as there's a great deal more likelihood I would hear about it.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#117
post #104

Earlier quoted context omitted.

You can verify closed source E2EE as long as you can inspect the traffic going client-server. The problem is that most E2EE apps allow auto-updating, so baking in something that transmits info to a third party is easy (but detectable with enough eyes on the code).

But what's stopping the software from, say, having a backdoor that is only exposed under certain conditions? For example, if you are under an FBI investigation. I suppose you could automate the verification on a per-call basis. Unfortunately, every bit over the wire would need to be seen by a fool-proof algorithm to ensure your safety. Seems not tractable.

Agreed. You can only verify E2EE for the traffic you inspect, not for traffic you don't. If they open-sourced the client it'd help a lot, but I'd also like to point out that you probably have stuff in your current device that has DMA and network access that is not open source either (PSP, IME, 4G modem, and so on) and that could break that encryption too.

If you are under serious investigation I wouldn't trust anything "smart" manufactured in a country under that investigations jurisdiction.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#118
post #27

Earlier quoted context omitted.

Because of its inevitable ties and implicit subservience to the CCP.

The only "relevant" information found in the quote in the GP comment is the nationality of the CEO. How does one jump from the CEO's nationality to inevitable ties and implicit subservience to CCP?

Didn't Zoom block a US based activist on the request of the Chinese government? I'm not arguing that there is complete subservience to the CCP but this censorship seems like a line was crossed.

https://www.nytimes.com/2020/06/11/technology/zoom-china-tia...

Edit: Let me also state that I'm not entirely sure what OP's argument was, considering the comment was deleted. I'm merely stating that there seems to be some cooperation with the CCP and Zoom.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#119

I find this story arch with Zoom amusing: 1. Pre-COVID Zoom claims it has E2E encryption for everyone. 2. During COVID Zoom grows in popularity, which prompts journalists to learn that the claims that Zoom has E2E encryption are inaccurate. 3. Zoom admits that it never had true E2E encryption, but announces they will develop it and it will only be available for paying customers. 4. Zoom gets another wave of criticism…

It wouldn't surprise me as recently the app tried to get me to trust an untrusted cert.

yikes, if they ended up murdering Keybase and still ship crap, I will never forgive them.

Re: Zoom to bring end-to-end encryption to all users, including non-paying

#120

Personally, I'm not feeling comfortable using Zoom on my PC. Just the other day, when opening the app, I was given a warning that the security certificate was untrusted and I would need to trust the certificate to proceed. I tried updating the app and the same error occurred. Perhaps their cert had expired or it was some oversight but I'm done. I've removed Zoom.

I only have it installed on a spare laptop that I leave off unless I'm doing a meeting.

100% do not trust.

Post reply on HN